Описание
Android SVG vulnerable to XML External Entity (XXE)
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Пакеты
Наименование
com.caverock:androidsvg
maven
Затронутые версииВерсия исправления
< 1.3
1.3
Связанные уязвимости
CVSS3: 7.8
nvd
около 8 лет назад
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution